Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: SolarWinds Serv-U Vulner Vulnerability Exploited
June 6, 2026
Critical RCE in Hugging Face Transformers Allows Attacks
June 6, 2026
Discover the Top 5 Best Simulated DDoS Attack Tools
June 6, 2026
Home/CyberSecurity News/Ivanti ITSM Flaw Grants Attackers Admin Privilege Vulnerability Lets
CyberSecurity News

Ivanti ITSM Flaw Grants Attackers Admin Privilege Vulnerability Lets

Ivanti has disclosed a high-severity vulnerability within its Ivanti Neurons for ITSM platform. Attackers with valid credentials could exploit this flaw to escalate privileges, ultimately gaining...

David kimber
David kimber
June 3, 2026 2 Min Read
16 0

Ivanti has disclosed a high-severity vulnerability within its Ivanti Neurons for ITSM platform. Attackers with valid credentials could exploit this flaw to escalate privileges, ultimately gaining full administrative access.

 The flaw, tracked as CVE-2026-9614, affects both cloud and on-premises deployments and has been assigned a CVSS score of 8.8, indicating a significant security risk in enterprise environments. The vulnerability stems from improper access control, categorized under CWE-284.

According to Ivanti, a remote authenticated attacker can exploit this issue without requiring user interaction, enabling unauthorized elevation to administrator-level permissions.

The CVSS vector highlights that the attack can be executed over the network with low complexity and limited privileges, while potentially impacting confidentiality, integrity, and availability.

Ivanti ITSM Vulnerability

Ivanti Neurons for ITSM is widely used for IT service management workflows, including ticketing, asset tracking, and automation.

Administrative access within such platforms can expose sensitive organizational data and allow attackers to manipulate system configurations or create persistent backdoors.

For example, an attacker with compromised low-level credentials could exploit CVE-2026-9614 to elevate privileges and modify user roles, effectively taking control of the ITSM environment. The vulnerability impacts on-premises versions 2025.4 and earlier.

Ivanti has released patches to address the issue in version 2025.4 Patch 1, as well as backported fixes in 2025.3 Patch 1 and 2025.2 Patch 1.

Organizations running affected versions are strongly advised to update immediately through the Ivanti License System portal.

For cloud customers, Ivanti has already applied fixes across all environments. The company confirmed that patches were deployed during updates rolled out on May 24 and 25, specifically in versions 2026.1 Patch 9 and 2026.2 Patch 1.

Additional updates were later issued to resolve a separate logging issue affecting IP address tracking. However, this secondary bug is unrelated to the core vulnerability.

At the time of disclosure, Ivanti stated that there is no evidence of active exploitation in the wild. However, given the ease of exploitation and the potential impact, the company issued an out-of-band security advisory to accelerate remediation efforts.

Ivanti also noted that there are currently no publicly available indicators of compromise associated with this vulnerability.

As a precaution, organizations are encouraged to audit role-based access controls and verify that administrative privileges are restricted to intended users. Misconfigured roles could increase exposure and make exploitation easier.

Security teams should prioritize patching and conduct internal reviews of access permissions within their ITSM deployments. Given the critical role these platforms play in enterprise operations, timely remediation is essential to prevent potential abuse by threat actors.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Apache ActiveMQ Vulnerability: Header Injection

Next Post

AI Tools Automate Active Directory Attacks & EDR Evasion

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Malicious Python Package Mimics Legitimate Parsimon
June 5, 2026
Hackers Weaponize Trusted Tools to Deploy Not Increasingly Weaponizing
June 5, 2026
Magecart Attack Uses Stripe as Malware Command Server
June 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us